CVE-2024-6632: SQL Injection in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)
Published Aug 27, 2024
·Updated
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.
Affected Software
1 affected component
Fortra FileCatalyst Workflow>=5.0.4<5.1.7
Remediation
Information
Upgrade to FileCatalyst Workflow 5.1.7 or later.
Event History
Aug 27, 2024
CVE Published
via MITRE·02:12 PM
Data Sourced
via MITRE·02:12 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6632?
CVE-2024-6632 has a high severity rating due to the potential for SQL injection attacks.
2
How do I fix CVE-2024-6632?
To mitigate CVE-2024-6632, upgrade to a version of Fortra FileCatalyst Workflow that is above 5.1.7 or below 5.0.4.
3
What are the potential impacts of CVE-2024-6632?
CVE-2024-6632 can lead to a loss of confidentiality, integrity, and availability if exploited.
4
Which versions of Fortra FileCatalyst Workflow are affected by CVE-2024-6632?
CVE-2024-6632 affects Fortra FileCatalyst Workflow versions between 5.0.4 and 5.1.7.
5
What type of vulnerability is CVE-2024-6632?
CVE-2024-6632 is classified as an SQL injection vulnerability.